Table of contents exchange of letters with the minister executive summary



Download 5.91 Mb.
View original pdf
Page148/329
Date27.11.2023
Size5.91 Mb.
#62728
1   ...   144   145   146   147   148   149   150   151   ...   329
Report of the COI into the Cyber Attack on SingHealth 10 Jan 2019

COI Report – Part IV
Page 173 of 425

remediation efforts across the various IHiS teams. The teams continued to operate largely in silos, and no meeting to consolidate all the findings and to decide on a concrete way forward was held until 9 July 2018, and, even then, apparently under the direction of Woon Lan.
28 EVENTS OF 9 JULY 2018
28.1 Shutting down Citrix Server 2
547. On 9 July 2018, at around pm, the Citrix Team shutdown Citrix Server 2. Lum was unable to recall who gave the instruction to do sob Meeting amongst various members of the Infrastructure

Services Division at pm
548. At around pm on 9 July 2018, Ernest coordinated a meeting attended by members of the SMD, the Citrix Team (including Lum), the Active Directory Team, Raymond, Wee, and Woon Lan, in her capacity as Deputy Director of the Infrastructure Services Division. The purpose of the meeting was to discuss the events of June and July 2018, including the unauthorised access to the Citrix servers and attempts to login to the SCM database, to correlate findings, and to discuss measures to tighten the security of the SingHealth network.
549. At or before the afternoon of 8 July 2018, the SMD was putting together a list of action items.
This list of action items was discussed at the meeting at pm on 9 July 2018 and was updated thereafter based on the discussion at the meeting. The updated list was distributed by Ernest to the relevant IHiS staff at pm that same day.
550. With reference to the list of action items, the focus of the discussion was on the list of technical and administrative measures to tighten the security of the network. However, in addition to these measures, the list of action items also recorded a number of notable events and considerations, which is indicative



COI Report – Part IV
Page 174 of 425

of what IHiS staff had known by that point in time. The updated version as of pm on 9 July 2018 that Ernest sent to the attendees included the following
NOTABLE EVENTS

A potential sucessful [sic] DB database dump […] a domain administrators account is already compromised even before Citrix breach the same domain administrators account is constantly being used to clear the logs

Priv account was removed from local admin group to deny
RDP but it was added back again
CONSIDERATIONS

What if Domain Controllers are compromised Potentially all LDC citrix servers are compromised. Consider checking with IHIS pentesting team, to check for common AD password dumping tools, and search for traces anywhere on SingHealth PCs/Servers […]
551. Wee has explained that the notable events and considerations listed above were shown during the meeting, but were not the focus of the meeting.
552. At the meeting, Woon Lan asked Wee for his assessment of the incident, and asked whether there was a need to escalate the matter to senior management.
33
Based on what was discussed at the meeting, he had “some
concerns that (he) was notable to confirm”, and that he “still thought it may not
be a security incident”.
553. Examples of such concerns include concerns over the fact that there were suspicious SQL queries on the SCM database, and that the AA. application account was being used. On the deletion of the Windows event logs, Wee was This is contrasted against Ernest’s claims in his conditioned statement that “At this meeting, we did not
discuss whether the matter should be escalated to IHiS senior management”.



Download 5.91 Mb.

Share with your friends:
1   ...   144   145   146   147   148   149   150   151   ...   329




The database is protected by copyright ©ininet.org 2024
send message

    Main page